Azure Defender: Major diff between CSPM or CWP Plan ?

$@chin 200 Reputation points
2025-03-16T21:06:37.5033333+00:00

What is the main difference between the CSPM and CWP Defender plans?

Can both plans be enabled within a subscription? If so, will enabling both result in double charges, or will they only incur a charge for one of the plans?

currently have the CWP plan for all resources, but under recommendations or security posture, it still shows "no risk calculated" or "not evaluated". which could be the concern.

Azure Cloud Services
Azure Cloud Services
An Azure platform as a service offer that is used to deploy web and cloud applications.
774 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Marcin Policht 50,735 Reputation points MVP Volunteer Moderator
    2025-03-16T21:08:46.51+00:00

    The main difference between CSPM (Cloud Security Posture Management) and CWP (Cloud Workload Protection) in Microsoft Defender for Cloud is:

    • CSPM Defender Plan focuses on identifying misconfigurations, compliance risks, and security posture weaknesses across cloud environments (Azure, AWS, GCP). It does not provide runtime protection but offers security assessments and recommendations.
    • CWP Defender Plan provides runtime protection for workloads like VMs, containers, Kubernetes, databases, and more. It offers threat detection, vulnerability assessment, and attack prevention for specific resources.

    Can both plans be enabled? Will there be double charges?
    Yes, both plans can be enabled within a subscription, as they serve different purposes. However:

    • They are billed separately based on the resources they protect.
    • There is no double charge for enabling both plans, but you will pay for each service individually based on its pricing model.

    Why is security posture showing "no risk calculated" or "not evaluated"?
    If you only have the CWP plan enabled and security posture is not being evaluated, it’s likely because:

    1. CSPM Defender is not enabled – Security posture is assessed by CSPM, not CWP.
    2. Insufficient permissions – Ensure the necessary Reader or Security Reader role is assigned to Defender for Cloud.
    3. Data collection or policy settings are misconfigured – Check the Defender for Cloud settings to ensure security assessments are running.
    4. Recent onboarding – If you recently enabled Defender for Cloud, it might take time for risk assessments to generate.

    If you need security posture evaluation, enable the CSPM Defender Plan in addition to CWP.


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin

    0 comments No comments

  2. Arko 4,150 Reputation points Microsoft External Staff Moderator
    2025-03-17T09:12:43.98+00:00

    Hello $@chin, I can see a similar question was answered on the MS QnA forum. Kindly check that once. Both plans can be enabled within a subscription and are billed separately based on the resources they protect. Enabling both does not result in double charges; instead, you pay for each service individually according to its pricing model. ​

    CSPM: Focuses on identifying misconfigurations, compliance risks, and security posture weaknesses across cloud environments as rightly mentioned by Marcin. It offers security assessments and recommendations but does not provide runtime protection. ​

    CWP: Provides runtime protection for workloads such as VMs, containers, AKS clusters, databases, and more. It includes threat detection, vulnerability assessments, and attack prevention for specific resources. ​

    Regarding the issue of security posture showing "no risk calculated" or "not evaluated," as Marcin has correctly highlighted that this is likely because CSPM is not enabled. CSPM is responsible for assessing security posture; without it, these evaluations won't occur. To address this, you should enable the CSPM Defender Plan in addition to CWP.

    Hope the suggestions and the QnA link provided were helpful. Thank you.


  3. Marcin Policht 50,735 Reputation points MVP Volunteer Moderator
    2025-03-20T15:44:56.1566667+00:00

    There is no possibility of "double charges" taking place, because these plans do not overlap in regard to the functionality they offer.

    There is no "server plan" under CSPM - that's CWP


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.